PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Facebook Accused of Misusing Two-Factor Auth for SMS Spam

The phone number Facebook requests for login authentication is also being used to tell you about friends' posts

 & Matthew Humphries Former Senior Editor

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

It seems as though Facebook is abusing the trust of security-conscious users of the social network in a bid to increase engagement. At least, that's the claim being made by software engineer Gabriel Lewis, who has the proof to back it up.

As The Verge reports, Facebook allows you to setup two-factor authentication (2FA) on your account to add an extra layer of security. In order to do that, though, Facebook requires you supply a phone number.

What Lewis discovered when he enabled 2FA was that Facebook assumed it was acceptable to then use his number to send SMS messages informing him when friends had posted on the social network. Even worse than that, though, attempting to respond to those text messages saw his responses appear on Facebook as posts.

Clearly, when you enable 2FA the focus is on security and you don't expect to automatically have your phone number opened up as a new engagement channel for Facebook. There was no opt-in or even opt-out presented, it was simply triggered by enabling 2FA.

Is this a bug or a feature? If it's a feature then Facebook could be facing another lawsuit with regards to violations of the Telephone Consumer Protection Act. I say another as one is already underway regarding the sending of unauthorized birthday reminder text messages.

About Our Expert

Matthew Humphries

Matthew Humphries

Former Senior Editor

My Experience

I started working at PCMag in November 2016, covering all areas of technology and video game news. Before that I spent nearly 15 years working at Geek.com as a writer and editor. I also spent the first six years after leaving university as a professional game designer working with Disney, Games Workshop, 20th Century Fox, and Vivendi.

I hold two degrees: a Bachelor's degree in Computer Science and a Master's degree in Games Development. My first book, Make Your Own Pixel Art, is available from all good book shops.

My Areas of Expertise

  • PC components and system building
  • Raspberry Pi
  • Software development
  • Storage technology
  • Video games and gaming hardware

Read full bio